
malvinci
This simple but powerful script will introduce a new type of malware that will turn off the firewall, start an HTTP server, forward its port through…

This simple but powerful script will introduce a new type of malware that will turn off the firewall, start an HTTP server, forward its port through…

A standalone Blind XSS Script.

Enhanced version of secretsdump.py from Impacket. Adds multi-threading and accepts an input file with a list of target hosts for simultaneous secrets…

Find interesting files stored on (System Center) Configuration Manager (SCCM/CM) shares via HTTP(s)

Curated collection of red team and pentest tools grouped by phase: payloads, AMSI bypasses, pivoting, persistence, privesc, credential harvesting,…

CVE-2026-7070 PoC for RDP clipboard hijacking via virtual channel injection; includes simulated server and exploit script for data theft/credential…

A bash script for easyly exploiting ImageMagick Arbitrary File Read Vulnerability CVE-2022-44268

Rogue-MySql-Server

A python script to create a fake GitHub runner and hijack pipeline jobs to leak CI/CD secrets.

Python script that will extract all saved passwords from your google chrome database on windows only

A python3 script that uses cl1p website to send and receive secret messages

A collection of data exfiltration scripts for Red Team assessments.

Better Remote Access Trojan

A python script that can detect and parse loki-bot (malware) related network traffic. This script can be helpful to DFIR analysts and security…

CVE-2023-24055 POC written in PowerShell.

Proof-of-concept Python script demonstrating iOS file exfiltration via malicious symlink in device backup restoration, targeting the…

An input validation vulnerability in Apache Superset allows an authenticated attacker to create a MariaDB connection with local_infile enabled,…

Stored XSS exploit for Roundcube Webmail ≤1.6.6 (CVE-2024-42009) with zero-click email exfiltration via CSS animation event handlers. Includes SMTP…